CVE-2026-40139

CRITICAL

BeyondTrust Remote Support - Unauthenticated Access Control Bypass

Title source: manual
STIX 2.1

Description

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (8)
BeyondTrust/Privileged Remote Access < 25.3.2
BeyondTrust/Privileged Remote Access < 25.3.3
BeyondTrust/Privileged Remote Access < 26.2.1
beyondtrust/privileged_remote_access < 25.3.3
BeyondTrust/Remote Support < 25.3.2
BeyondTrust/Remote Support < 25.3.3
BeyondTrust/Remote Support < 26.2.1
beyondtrust/remote_support < 25.3.3
Published Jul 06, 2026
Tracked Since Jul 06, 2026